Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion docs/usage.md
Original file line number Diff line number Diff line change
Expand Up @@ -476,7 +476,7 @@ on subsequent fetches and SSE reconnects.
**WARNING: This is a dangerous option that disables security protections. Use only if you understand the implications.**

- **Purpose**: Controls whether Codex runs with sandbox protection
- **Default**: Not set (uses `--full-auto` with sandbox protection)
- **Default**: Not set (uses `--sandbox workspace-write` with sandbox protection)
- **Values**:
- `true` or `1`: Bypasses Codex sandbox and approvals (uses `--dangerously-bypass-approvals-and-sandbox`)
- Any other value or unset: Uses safe mode with sandbox
Expand Down
3 changes: 2 additions & 1 deletion hooks/loop-codex-stop-hook.sh
Original file line number Diff line number Diff line change
Expand Up @@ -1208,7 +1208,8 @@ if [[ -n "$CODEX_EXEC_EFFORT" ]]; then
CODEX_EXEC_ARGS+=("-c" "model_reasoning_effort=${CODEX_EXEC_EFFORT}")
fi

CODEX_AUTO_FLAG="--full-auto"
# Same sandbox the removed --full-auto flag selected (see scripts/ask-codex.sh)
CODEX_AUTO_FLAG="--sandbox=workspace-write"
if [[ "${HUMANIZE_CODEX_BYPASS_SANDBOX:-}" == "true" ]] || [[ "${HUMANIZE_CODEX_BYPASS_SANDBOX:-}" == "1" ]]; then
CODEX_AUTO_FLAG="--dangerously-bypass-approvals-and-sandbox"
fi
Expand Down
4 changes: 3 additions & 1 deletion scripts/ask-codex.sh
Original file line number Diff line number Diff line change
Expand Up @@ -277,7 +277,9 @@ if [[ -n "$CODEX_EFFORT" ]]; then
fi

# Determine automation flag based on environment variable
CODEX_AUTO_FLAG="--full-auto"
# Newer Codex CLIs removed --full-auto. For `codex exec` it only selected the
# workspace-write sandbox, which --sandbox provides on every supported version.
CODEX_AUTO_FLAG="--sandbox=workspace-write"
if [[ "${HUMANIZE_CODEX_BYPASS_SANDBOX:-}" == "true" ]] || [[ "${HUMANIZE_CODEX_BYPASS_SANDBOX:-}" == "1" ]]; then
CODEX_AUTO_FLAG="--dangerously-bypass-approvals-and-sandbox"
fi
Expand Down
40 changes: 40 additions & 0 deletions tests/test-ask-codex.sh
Original file line number Diff line number Diff line change
Expand Up @@ -325,6 +325,46 @@ else
fi
reset_mock

# Test: default run selects the workspace-write sandbox without the removed --full-auto flag
reset_mock
export MOCK_CODEX_STDOUT="sandbox-flag-test"
ASK_CODEX_ARGS_FILE="$TEST_DIR/ask-codex-sandbox-args.txt"
export MOCK_CODEX_ARGS_FILE="$ASK_CODEX_ARGS_FILE"
EXIT_CODE=0
run_ask_codex "sandbox flag test" > /dev/null 2>&1 || EXIT_CODE=$?
CAPTURED_ARGS="$(cat "$ASK_CODEX_ARGS_FILE" 2>/dev/null || true)"
if [[ $EXIT_CODE -eq 0 ]] \
&& echo "$CAPTURED_ARGS" | grep -qx -- '--sandbox=workspace-write' \
&& ! echo "$CAPTURED_ARGS" | grep -qx -- '--full-auto'; then
pass "default run uses --sandbox=workspace-write instead of --full-auto"
else
fail "default run uses --sandbox=workspace-write instead of --full-auto" \
"exec args include --sandbox=workspace-write and no --full-auto" \
"exit=$EXIT_CODE, args=$CAPTURED_ARGS"
fi
reset_mock

# Test: HUMANIZE_CODEX_BYPASS_SANDBOX still replaces the sandbox flag
reset_mock
export MOCK_CODEX_STDOUT="bypass-flag-test"
ASK_CODEX_ARGS_FILE="$TEST_DIR/ask-codex-bypass-args.txt"
export MOCK_CODEX_ARGS_FILE="$ASK_CODEX_ARGS_FILE"
export HUMANIZE_CODEX_BYPASS_SANDBOX="1"
EXIT_CODE=0
run_ask_codex "bypass flag test" > /dev/null 2>&1 || EXIT_CODE=$?
unset HUMANIZE_CODEX_BYPASS_SANDBOX
CAPTURED_ARGS="$(cat "$ASK_CODEX_ARGS_FILE" 2>/dev/null || true)"
if [[ $EXIT_CODE -eq 0 ]] \
&& echo "$CAPTURED_ARGS" | grep -qx -- '--dangerously-bypass-approvals-and-sandbox' \
&& ! echo "$CAPTURED_ARGS" | grep -qx -- '--sandbox=workspace-write'; then
pass "HUMANIZE_CODEX_BYPASS_SANDBOX=1 replaces the sandbox flag"
else
fail "HUMANIZE_CODEX_BYPASS_SANDBOX=1 replaces the sandbox flag" \
"exec args include --dangerously-bypass-approvals-and-sandbox only" \
"exit=$EXIT_CODE, args=$CAPTURED_ARGS"
fi
reset_mock

# ========================================
# Error Handling Tests
# ========================================
Expand Down
8 changes: 8 additions & 0 deletions tests/test-disable-nested-codex-hooks.sh
Original file line number Diff line number Diff line change
Expand Up @@ -222,6 +222,14 @@ else
"exec --disable hooks --disable plugin_hooks --disable codex_hooks" "$(cat "$TEST_DIR/impl.args" 2>/dev/null || echo missing)"
fi

if grep -q -- '--sandbox=workspace-write' "$TEST_DIR/impl.args" \
&& ! grep -q -- '--full-auto' "$TEST_DIR/impl.args"; then
pass "implementation-phase stop hook uses --sandbox=workspace-write instead of --full-auto"
else
fail "implementation-phase stop hook uses --sandbox=workspace-write instead of --full-auto" \
"--sandbox=workspace-write and no --full-auto" "$(cat "$TEST_DIR/impl.args" 2>/dev/null || echo missing)"
fi

REPO_REVIEW="$TEST_DIR/repo-review"
setup_repo "$REPO_REVIEW"
run_loop_hook "$REPO_REVIEW" "$TEST_DIR/review.args" "true"
Expand Down